Resolving Siemens HMI-PLC Communication Loss After Program Update

David Krause15 min read
HMI ProgrammingSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Resolving Siemens HMI-PLC Communication Loss After Program Update

A Siemens HMI panel or PC-based WinCC Runtime loses its S7 connection to a SIMATIC S7-1200 or S7-1500 PLC immediately after a newly compiled TIA Portal project is loaded onto the HMI. The PLC is still reachable on the PROFINET network (ping returns a reply), the previous HMI runtime project still connects without modification, and the failure only appears with the freshly compiled version. This article isolates the engineering root causes of that pattern and provides step-by-step restoration procedures referenced to official Siemens documentation.

Scope. This guide targets HMI panels in the SIMATIC HMI family (KTP, TP, Comfort, Unified Comfort) running WinCC Runtime Advanced or WinCC Unified, and PC-based runtime systems (WinCC Runtime Advanced, WinCC Runtime Professional, WinCC Unified PC) connected to S7-1200/1500 controllers programmed in TIA Portal V15 and later. Procedures assume PROFINET (Ethernet/IP) transport.

1. Problem Description and Failure Pattern

The failure has a very specific signature that helps narrow root cause analysis before opening any tooling:

  • The HMI displays a connection alarm of the form "Connection to PLC failed", "No connection to S7 controller", or carries a red connection status indicator in the screen.
  • ICMP ping from a laptop or the HMI itself to the PLC IP address succeeds — Layer 3 connectivity is intact.
  • Reverting the HMI to a previously compiled runtime project (transferred previously via USB, Ethernet, or by loading the .fwx / .bin / .targ file) restores the connection immediately.
  • The PLC program is unchanged in functional terms, or the PLC was not reloaded at all — only the HMI project was re-compiled and re-transferred.

This signature rules out a hardware fault, a cable issue, or a PLC firmware change. The cause is in the engineering data: the TIA Portal project that produced the new runtime no longer matches what the PLC expects on the S7 connection.

2. Root Cause Matrix

# Root Cause Typical Symptom Quick Check
1 PG/PC interface / Access Point on the engineering station or Panel PC is set to a different adapter (e.g., Realtek instead of Intel PROFINET, or WLAN instead of LAN) than the PLC subnet. Online > Accessible nodes lists no S7 device; HMI compiles fine but never opens the S7 channel. Start > SIMATIC > PG/PC Interface or Control Panel > Set PG/PC Interface.
2 New HMI project points to a different PLC IP address, rack/slot, or connection name than the live controller. WinCC connection status = DISCONNECTED with alarm 140001 / 140003 in diagnostics buffer. Open HMI project > Connections > verify IP, rack 0 / slot 1 (S7-1500) or slot 1 (S7-1200).
3 The TIA Portal version that produced the runtime differs from the version of the TIA Portal project stored on the engineering PC — project is opened with a newer SP than was used to install the HMI image. Runtime boots but logs version mismatch warnings; HMI connection table references undefined tags. TIA Portal > Project > Properties > Project information > compare Version field.
4 HMI device version in the device catalog was changed during recompile (e.g., from 6AV2 124-1MC01-0AX0 to 6AV2 124-1MC05-0AX0) and the panel image does not support the new image version. Runtime aborts during start; panel remains in transfer mode. Compare Device > Device version in the project with the MLFB printed on the back label of the panel.
5 PLC access protection (S7-1500: Connection mechanisms; S7-1200: Access level) was tightened in the new PLC program, blocking the HMI as an unknown PUT/GET client. HMI connection refused; S7 diagnostic buffer entry "Connection denied — insufficient access level". PLC > Properties > Protection & Security > Connection mechanisms.
6 Symbolic / absolute addressing mismatch. HMI tags re-resolved after project reorganization and now point to wrong DB offsets. Some screens read correct values, others show 0 or 16#FFFF; connection status itself is up. Cross-check HMI tag table against PLC watch table online.
7 TIA Portal automatically added a second S7 connection when the project was recompiled, leaving the original connection orphaned in the PLC. First HMI-to-PLC channel works, but the one referenced by the new runtime does not. Online > Accessible nodes > PLC > Diagnostics > Connections.
8 WinCC Runtime not restarted after the new project was transferred — the panel or PC runtime cached the previous project. Connection still shown in the runtime as the old name; alarms are stale. Restart WinCC Runtime: ProSave > Reboot or Start > Programs > SIMATIC > WinCC Runtime > Stop / Start.
9 Windows Firewall on a PC-based runtime (IPC227, IPC627, IPC677, IPC847, or third-party Panel PC) blocks S7 ports TCP 102 after a Windows update. Runtime starts but SIMATIC S7 Protocol Suite channel stays at "Disconnected". wf.msc > Inbound Rules > enable SIMATIC S7DOS Help / S7 protocol inbound rule.
10 USB transfer was used on a Windows-based runtime that requires Ethernet transfer, or the .bin file does not match the panel image (legacy KTP vs. Comfort). Runtime shows old project or boot loop; Backup/Restore dialog rejects file. ProSave > Info > confirm Image version, then re-select the correct transfer channel.

3. Prerequisites for Diagnosis

Confirm the following are available before opening TIA Portal:

  1. Working baseline. The previous HMI runtime project file (.ap16 / .ap17 / .ap18 / .ap19 / .zap16 / .zap17 / .zap18 / .udz) that is known to communicate.
  2. TIA Portal installation matching the project. TIA Portal V16 uses .ap16, V17 uses .ap17, V18 uses .ap18, V19 uses .ap19. Mismatched versions silently upgrade and may shift HMI device versions.
  3. PLC project archive (or at least the hardware configuration with rack, slot, and IP address) to cross-check against the HMI connection table.
  4. ProSave (Siemens tool, part of the SIMATIC HMI toolset) installed on the engineering PC for panel image / version inspection.
  5. Administrator rights on the engineering PC and on the Panel PC if the runtime is PC-based. PG/PC interface settings require administrative elevation.
  6. Network access to the PLC subnet. A simple ping <PLC IP> from the engineering PC validates Layer 3. If ping fails, fix IP routing before proceeding.

4. PG/PC Interface and Access Point Configuration

The most common cause of "ping works but TIA Portal cannot reach the PLC" is a misconfigured access point. Siemens consolidates the procedure in Entry ID 24109937 — "Which settings must be made in the PG/PC interface for communication between the HMI device and the PLC?" The key settings are:

  1. Open Control Panel > Set PG/PC Interface (Windows 10/11) or the SIMATIC-specific PG/PC Interface shortcut.
  2. In the Application Access Point dropdown, select S7ONLINE (STEP7) for direct TIA Portal online access or S7ONLINE (HMI) → <adapter> if the panel is to be reached through a routed gateway.
  3. For the interface parameterization, point to the Ethernet adapter that is physically connected to the PLC subnet. Disable the Wi-Fi adapter in the list to prevent the OS from binding S7 communications to the wrong NIC.
  4. Confirm the PG/PC is the only master on the bus is unchecked unless you are running FDL/Profibus, which is not the case for PROFINET HMI panels.
  5. Close the dialog, restart TIA Portal, and re-attempt Online > Accessible nodes.
Engineering station with multiple NICs. If the engineering PC has both a corporate network and the plant network, Windows may route S7 traffic out the corporate gateway if the binding is not forced. Use route print in an elevated command prompt to confirm the PLC subnet is reachable on the bound interface, and disable the corporate adapter in the PG/PC interface dialog.

5. TIA Portal HMI Connection Verification

With network access proven, open the failing HMI project in TIA Portal and inspect every S7 connection in the Connections editor of the HMI device.

5.1 Verify PLC Address Parameters

Parameter Expected Value (S7-1200) Expected Value (S7-1500) Where to Verify on the Live PLC
IP address Matches the X1 / X2 interface address configured in the PLC online Same Online > Accessible nodes > PLC > Online & diagnostics > PROFINET interface
Rack 0 0 Device configuration > Device view > CPU
Slot 1 1 (CPU 1505SP / 1507S / 1508S may differ for ET 200SP) Same
Connection type S7 connection (PUT/GET) or HMI connection S7 connection with active connection establishment by HMI PLC properties > Protection & Security > Connection mechanisms

If the HMI was originally connected to a CPU 6ES7 315-2EH14-0AB0 (S7-300) and the new project was edited to a 6ES7 515-2AM02-0AB0 (S7-1500), the rack/slot and OPC/connection mechanism will differ. The old project will fail if its connection was set to an S7-300 rack/slot convention.

5.2 Verify Connection Name and ID Uniqueness

If the new HMI project contains more than one S7 connection (for example, one to the main PLC and one to a sub-PLC), TIA Portal auto-numbers them. Connection 1 is reserved for the default connection; reusing names like HMI_Connection_1 across the project can produce shadowed connections. Each HMI tag must be re-resolved to the correct connection if the project was reorganized.

5.3 Recompile the HMI Project

Right-click the HMI device > Compile > Software (rebuild all). A full rebuild is mandatory after a TIA Portal upgrade or after importing a project from a different version — incremental compile can leave stale connection tables in the runtime image.

6. WinCC Runtime Transfer and USB Loading Procedure

For PC-based HMI runtimes, the runtime project is typically transferred by one of three methods:

  1. Ethernet transfer (preferred): TIA Portal > HMI device > Online > Download to device with the runtime set as target. Requires the PG/PC interface to be correct (see Section 4).
  2. USB transfer: Export the runtime from TIA Portal as a backup (.targ file for WinCC Unified, .zap for WinCC Advanced). On the panel, insert the USB, open Control Panel > Service & Commissioning > Backup/Restore, and select the .targ/.zap file. The panel will reboot into the new runtime.
  3. ProSave transfer: Open ProSave on the engineering PC, select the panel IP or USB connection, then push the .targ/.zap file. ProSave is required when the panel image must also be updated.
Cold restart required. Comfort and Unified Comfort panels do not hot-swap projects. After any project transfer, perform a controlled restart from Control Panel > Reboot or from ProSave > Restart. A warm reboot that simply re-launches the runtime cache can leave the old project in memory.

6.1 Validating the Transferred Project

After the restart, open the runtime diagnostics page (usually reachable via a hidden corner gesture or by holding the top-left of the screen for 5 seconds on a Unified Comfort panel). Confirm:

  • Runtime project name and version match the new project.
  • Connection status for each S7 connection is green / Established.
  • System diagnostics view (under Diagnostics > Connections) lists the connection endpoints and the locally bound port (typically TCP 102 for S7).

7. PLC Connection Protection on S7-1200 and S7-1500

S7-1200 and S7-1500 CPUs support access protection that can silently block the HMI when the protection level is raised.

7.1 S7-1200 (firmware V4.x and later)

  1. Open the PLC device configuration in TIA Portal.
  2. Navigate to Properties > Protection & Security > Access level.
  3. Confirm HMI access is allowed. On S7-1200, the Full access (no protection) or Read/write access levels are required for HMI write operations. The HMI access checkbox is the master switch that, when unchecked, blocks the HMI entirely even if the IP and connection name are correct.

7.2 S7-1500 (firmware V2.0 and later)

  1. Open the PLC device configuration in TIA Portal.
  2. Navigate to Properties > Protection & Security > Connection mechanisms
  3. Confirm Permit access with PUT/GET communication from remote partner is enabled or that the HMI connection is configured as an S7 connection with active establishment by HMI, in which case the PLC-side access check is bypassed.
  4. If the CPU is in Secure Communication mode (TLS), the HMI must be configured with the same security settings and the CPU certificate must be trusted by the panel. TIA Portal V17 SP1 and later enforce this automatically; older runtimes may not support TLS and will fail to establish the secure channel.
Symptom of tightened protection. If the HMI connection fails immediately after a PLC download (and the HMI was not reloaded), the most likely cause is that the new PLC program raised the access level. The previous PLC program permitted the connection; the new one does not.

8. HMI Device Image and TIA Portal Version Compatibility

HMI device image version is a frequent silent failure source. Each Comfort, KTP, and Unified Comfort panel has an MLFB (order number) of the form 6AV2 xxx-xxx xx-0AX0. The last two characters (e.g., 0AX0, 0AX3, 0AX4) denote the hardware revision and, frequently, the image version.

Typical MLFB Pattern Example Compatible TIA Portal Image Update Required For
6AV2 124-1MC01-0AX0 (KTP400 Comfort) KTP400 Comfort, 4" TIA V13 SP1 / V14 / V15 V15 SP1 image via ProSave
6AV2 124-1MC05-0AX0 KTP400 Comfort, 4" (newer) TIA V16 / V17 / V18 / V19 V17 image or later
6AV2 125-2AE13-0AX0 (TP1500 Comfort) TP1500 Comfort, 15" TIA V15.1 / V16 / V17 V17 image recommended for TLS
6AV2 125-2GB10-0AX0 (TP1900 Comfort) TP1900 Comfort, 19" TIA V15.1 onward V17 image for full WinCC Unified upgrade
6AV2 127-1AD10-0AX0 (Unified Comfort) MTP700 Unified TIA V17 / V18 / V19 V18 image required for full WinCC Unified V18 feature set

If the new TIA Portal project was compiled for a different MLFB than the panel reports in ProSave > Info, the runtime will either fail to start or load a fallback image. To verify:

  1. Open ProSave and connect to the panel (USB or Ethernet).
  2. Click Info. The reported MLFB must match the Device version in the TIA Portal project > HMI device > Properties > General > Device.
  3. If they differ, either re-target the project in TIA Portal to the correct MLFB (drag the new device from the catalog) or update the panel image via ProSave > Update OS.

9. Network Layer Verification

Even with a successful ICMP ping, the S7 protocol (TCP port 102) may be blocked. Validate the following:

Check Command / Method Pass Criterion
TCP 102 reachable from engineering PC Test-NetConnection <PLC IP> -Port 102 (PowerShell) or tcping <PLC IP> 102 TcpTestSucceeded: True
Subnets and gateway consistent ipconfig /all on PC, compare to PLC online Same subnet, no IP conflict
No duplicate IP Unplug the panel, ping the PLC IP from the engineering PC, then re-plug panel; check for ARP conflicts Single ARP entry per IP
Switch port configuration Confirm the panel and PLC are on the same VLAN, no port security blocking the S7 MAC Untagged VLAN, no MAC lockout
Windows Firewall on Panel PC wf.msc > Inbound Rules > SIMATIC S7 protocol rule enabled Rule enabled and bound to the active profile
Antivirus / EDR Temporarily disable to test; if communication is restored, add a rule for the WinCC Runtime process No inbound block on TCP 102

10. Verification Checklist

After applying the corrective actions, perform the following sequence to confirm the new HMI project communicates reliably:

  1. Restart the HMI from Control Panel > Reboot (or ProSave > Restart). Do not rely on a hot reload of the runtime.
  2. Open the HMI diagnostics screen. Confirm connection status is green / Established for every defined S7 connection.
  3. Force a value change from the HMI to a writable tag (e.g., set a marker M0.0) and verify in TIA Portal Monitor & Force that the value reached the PLC.
  4. Force a value change in the PLC (Monitor & Force > Modify) and confirm the HMI screen reflects the new value within one update cycle (default 1 s).
  5. Power-cycle the HMI and the PLC in the operational sequence. Confirm the HMI re-establishes the S7 connection on the first or second reconnect attempt without operator intervention.
  6. Archive a working backup of the runtime project via Backup in the panel control panel and store it in the project library. Future regressions can be reverted in under two minutes.

11. Preventive Measures and Best Practices

  1. Lock the TIA Portal version. Open the project in the same TIA Portal version that produced the running runtime. If you must upgrade, upgrade the panel image first, then recompile the project.
  2. Document the PG/PC interface selection. Save the working access point selection in a project-specific README. Many communication faults traced back to a laptop swap that changed the bound NIC.
  3. Use project-wide IP constants. Define PLC IP addresses in TIA Portal > Project tree > PLC & devices > Device > Properties > PROFINET interface as constants. Reference these from the HMI connection. This eliminates the most common manual re-entry error.
  4. Version the runtime images. Maintain a chronologically ordered backup of the working .targ / .zap / .udz files. When a regression appears, roll back to the last known-good image and diff the engineering data.
  5. Test compile & transfer on a bench. For multi-engineer projects, integrate an offline test rig with a real S7-1500 CPU that mirrors the production IP scheme. Run a smoke test (write a tag, read it back) on every commit that changes the HMI project.
  6. Disable Windows auto-updates on production Panel PCs. Windows cumulative updates frequently re-enable firewall rules and re-introduce TCP 102 blocks. Lock the OS update channel and apply patches on a controlled maintenance window.

12. Frequently Asked Questions

Why can I ping the PLC but the HMI still shows "No connection"?

ICMP is a Layer 3 echo. S7 communication uses TCP port 102 and is independent of ICMP. A Windows firewall, antivirus, or switch ACL can block TCP 102 while leaving ICMP untouched. Run Test-NetConnection <PLC IP> -Port 102 from PowerShell; if it returns False, the S7 port is blocked at the OS, EDR, or network layer.

My old HMI project works but my new one does not. What is the most likely cause?

The most common cause is that the new TIA Portal project references a different PLC IP address, rack/slot, or connection name. Open the HMI > Connections editor and verify every parameter against the live PLC online configuration. The second most common cause is that the TIA Portal version used to produce the new runtime differs from the version of the HMI image, requiring an OS update via ProSave.

Do I need to re-flash the panel image to fix this?

Usually no. A panel image re-flash is only required when the MLFB or TIA Portal version changed. For same-version projects, the fix is in the engineering data (connection parameters, PG/PC interface, access protection) and a clean project recompile plus restart of the runtime. Use ProSave > Info to confirm the current image version before any OS update.

How do I confirm the HMI is using the new project after USB transfer?

Open the runtime diagnostics page (Control Panel > OP > Information > System or the System screen on Unified Comfort). The reported project name, version, and compilation date must match the new project. If they do not, the runtime was not restarted after the transfer.

Where can I find the official Siemens guide for PG/PC interface setup?

Siemens consolidates the access point and adapter selection procedure in Entry ID 24109937 — "Which settings must be made in the PG/PC interface for communication between the HMI device and the PLC?" on the Siemens Industry Online Support portal.

Back to blog